Home

Description

A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.

PUBLISHED Reserved 2024-01-17 | Published 2024-07-09 | Updated 2024-08-01 | Assigner Ping Identity




LOW: 3.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

Problem types

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

11.0.0
affected

11.1.0
affected

11.2.0
affected

11.3.0
affected

12.0.0
affected

References

docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083

cve.org (CVE-2024-21832)

nvd.nist.gov (CVE-2024-21832)

Download JSON